Mainstream cloud storage
ImageTome vs Dropbox
Dropbox is a file syncing product that a lot of people use as a photo and video sharing product. It is reliable and it is not trying to mislead anyone about its encryption, but it is not end-to-end encrypted and it does not claim to be.
Dropbox encrypts the disk. We encrypt the file, in your browser, with a key Dropbox's architecture has no equivalent of.
Side by side
| Criterion | ImageTome | Dropbox |
|---|---|---|
| Encryption model | ImageTome End-to-end. AES-256-GCM in the browser, before upload. | Dropbox AES-256 at rest and TLS in transit. No client-side encryption and no user-held keys. |
| Who holds the keys | ImageTome You. An RSA-4096 private key generated on your device and never sent to us. | Dropbox Dropbox. There is no supported way to bring your own key on consumer plans. |
| What an account needs | ImageTome A username. No email address, no password, no phone number. | Dropbox An email address and password, or a linked Google or Apple account. |
| If you lose access | ImageTome Nothing we can do. Your exported key backup is the only route back in. | Dropbox Standard password reset by email. Deleted files recoverable for 30 days or more. |
| Filenames and titles | ImageTome Encrypted. Tome names, descriptions, filenames, titles and post bodies. | Dropbox Filenames, folder structure and file sizes are readable by Dropbox. |
| Content scanning | ImageTome None, and none is possible. Nothing here is detected proactively, because nothing can be read. | Dropbox Automated scanning for copyright matches and prohibited content. A small number of staff can access user data in defined circumstances. |
| Video | ImageTome MP4 and WebM up to 200MB, with thumbnails generated and encrypted in the browser. | Dropbox Large files, previews and streaming, with generous size limits. |
| Sharing | ImageTome Invite by username. The tome key is wrapped with their public key. | Dropbox Shared links and shared folders, optionally password protected. Dropbox can read the contents. |
| Discussion | ImageTome Encrypted comments on posts, images and videos. | Dropbox Comments on files and folders. |
| Verifying the claim | ImageTome Open your network tab during an upload and read what is actually sent. | Dropbox You cannot. Dropbox publishes its security measures, but the keys are on its side by design. |
Encryption at rest solves a different problem
Encryption at rest is protection against a stolen disk, a decommissioned drive, a misconfigured bucket. It is worth having and Dropbox does it properly with AES-256. What it does not do is stop the service itself from reading your files, because the service holds the keys. Dropbox is explicit about this: it does not offer client-side encryption and does not support user-supplied private keys.
That is not a scandal, it is a design choice with real benefits. Server-side keys are what make full-text search, web previews, thumbnail generation, version history and 30-day undelete possible. You cannot generate a preview of a file you cannot read.
ImageTome made the opposite choice, and pays for it in exactly those features. Your image is encrypted with AES-256-GCM in the browser and uploaded as ciphertext. Its thumbnail is generated on your device and encrypted too. Its filename is encrypted. We have no preview service because we have nothing to preview.
Who can reach your files
Dropbox states that a small number of employees can access user data in narrow circumstances, such as when legally compelled, under strict policy and technical controls. That is an honest and fairly typical disclosure, and the controls are real. It is still a list of people who could, under some circumstances, look.
On ImageTome that list is empty, and not because we are more virtuous. Our staff, our hosting provider and anyone who compels us all get the same thing: encrypted blobs and the public keys they were wrapped for. There is no privileged internal view, because there is no key to build one with.
Shared links are the weak point
A Dropbox shared link is a URL that grants access to whoever holds it. Password protection and expiry help, but the underlying file is readable by Dropbox throughout, and a leaked link is a leaked file.
An ImageTome invitation is a key exchange, not a URL. The tome key is wrapped with the invited member's RSA-4096 public key, so only their device can unwrap it. There is no link that leaks access, because access is not a link.
When Dropbox is the better choice
- For general file syncing across desktops with version history and 30-day recovery, Dropbox is a far better tool than we are. We do not sync folders and we do not have a trash.
- For sharing files with people who will not sign up for anything, a Dropbox link works and our invitations do not. Sharing here requires the other person to have an account with a keypair.
- For very large files and long videos, Dropbox's limits are much higher than our 200MB per video.
ImageTome and Dropbox, asked and answered
No. Dropbox encrypts files in transit with TLS and at rest with AES-256, but holds the encryption keys itself. It does not offer client-side encryption on consumer plans, which means the encryption does not exclude Dropbox.
Dropbox says a small number of employees can access user data in limited circumstances, such as legal compulsion, under strict controls. The capability exists by design, unlike an architecture where no key is held at all.
Yes, with a tool like Cryptomator, and it is a good option if you want to keep using Dropbox. It also means managing an extra tool, and it does not encrypt filenames or make sharing easy. ImageTome builds that in.
Up to 200MB per video, in MP4 or WebM. Images are up to 50MB each, with up to 25 per post. Dropbox's limits are much higher.
Sources
- Encryption for cloud storage, Dropbox
- Dropbox security measures (PDF)
- Cloud storage: how secure are Dropbox, OneDrive, Google Drive and iCloud? IT Pro
Claims about Dropbox were checked against the sources above on 30 August 2026. Products change. If something here is out of date or wrong, we would rather fix it than keep it.
Other comparisons
vs Google Photos
Google encrypts your photos and keeps the keys. We encrypt your photos and never have the keys.
Mainstream cloud photosvs iCloud Photos
Apple's end-to-end encryption is opt-in, platform-locked and withdrawn in the UK. Ours is the only mode we have.
End-to-end encrypted storagevs Proton Drive
Proton is a general encrypted drive with an account you can recover. We are an encrypted media space with an account nobody can recover, including us.
Try the version where nobody holds your key.
One username, one tome, and a look at your own network tab to check we mean it.
Create an account